• On CBSNews.com: Can 365 Nights Of Sex Fix A Marriage?
January 8, 2008 11:02 AM PST

First iPhone Trojan horse reported

Posted by Robert Vamosi
  • Print

Seen more as a prank than an actual threat, a Trojan horse for the Apple iPhone, first reported on Saturday, has already come and gone. Still, users should be on the look out for a package called "iPhone firmware 1.1.3 prep," described as something you need to install before updating to the new 1.1.3 firmware. Billed as an "important system update," the code does little more than cause annoyance. According to various sources, once the Trojan is installed it simply displays the word "shoes."

However, the Trojan also overwrites several legitimate applications, including Erica's Utilities, Launcher, Doom, and OpenSSH, meaning that if you uninstall the Trojan, you will need to reinstall these applications later. This appears to be a consequence of poor programming.

The risk to iPhone users is now considered negligible since the host sites have all been taken down.

As antivirus vendor F-Secure concluded in its blog, "This time it was an 11-year-old kid playing with XML files who created the Trojan. Next time it might be someone else with more skills and with specific target."

Recent posts from Defense in Depth
How to handle ID fraud's youngest victims
Is white listing going mainstream?
How Live OneCare changed the antivirus landscape
Express Scripts clients threatened with extortion
Study: DDoS attacks threaten ISP infrastructure
Add a Comment (Log in or register) 6 comments
Locked or Unlocked?
by Lee in San Diego January 8, 2008 12:59 PM PST
From what I read on other news sites this trojan only affect
unlocked iPhones.
Reply to this comment
Legitimate Applications!!!???
by MadKiwi January 8, 2008 1:51 PM PST
Crap. Those are NOT legitimate applications and are only present on hacked iPhones.
Reply to this comment
You wouldn't know that
by Lee in San Diego January 8, 2008 2:33 PM PST
You wouldn't know that from the how the headline reads. It would
be more accurate to read:

"Hacked iPhones Hacked to Death by Trojan!"
"Police Suspect Child's Play"
Impossible!!!
by Zmeson January 8, 2008 3:54 PM PST
Apple does *NOT* make operating systems or gadgets that have security holes!
Reply to this comment
You maybe correct!
by Lee in San Diego January 8, 2008 7:55 PM PST
Apple did not make this security hole.
You left out a few things...
by scweezil January 8, 2008 7:12 PM PST
You have to wonder why? Also you seem to mislead your readers by
saying it Masquerades as a firmware update for the iPhone which it
does not:

The Trojan specifically targets users that have modded their iPhone
so they can install third-party applications. The application masks
itself as an update to Erica?s Utilities and is labeled as ?113 prep.
Reply to this comment
advertisement

In the news now

Apple's iPhone 2.2
hits the street

The latest software update offers several improvements to Google maps as well as wireless downloading for podcasts.



The big chill for holiday parties?

Tech companies faced with cost-cutting may not be canceling the annual festivities outright, but things are certainly being done differently this year.



About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right